Global Threat Campaign Hits Critical VMware vCenter Flaw

A Global Threat Campaign Exploits Critical VMware vCenter Flaw, Leaving Victims Vulnerable Despite Patching

In a disturbing example of how quickly attackers can move on newly disclosed vulnerabilities, a single threat actor has been exploiting a critical flaw in VMware’s vCenter software since just days after its public disclosure. The vulnerability, CVE-2026–59310, allows an attacker with network access to a vCenter instance to execute arbitrary code in the target’s virtual environment, putting thousands of organizations at risk.

The exploitation began on August 3, less than a week after VMware publicly disclosed the flaw on July 29. According to German incident-response firm QUIRSO, which investigated the activity, the threat actor is using a tool called reverse_ssh, an open-source penetration testing tool, to establish persistence in compromised systems. This means that even if organizations patch their vCenter instances, they may still be vulnerable to further attacks.

QUIRSO’s research team identified 361 unique IP addresses impacted by the threat campaign, with the US, France, Iran, and Turkey being the most heavily targeted nations. The company’s chief operations officer, Denis Szadkowski, warns that patching alone may not be enough to fully mitigate the threat. “It is essentially a race between exploitation and patching,” he says. “We therefore recommend a forensic investigation of potentially affected systems to rule out an existing compromise.”

The fact that this campaign was carried out by a single threat actor highlights the sophistication and organization behind the attack. While it’s possible that the attacker had prior knowledge of the vulnerability, QUIRSO notes that the short window between public disclosure and exploitation suggests that the attacker may have been able to quickly develop an exploit after analyzing the patch.

For VMware customers, this presents significant challenges in terms of patching their vCenter instances. With a small window of only five days from disclosure to exploitation, organizations must act swiftly to protect themselves. Matt Snyder, principal engineer and detection and response lead at Aviatrix, notes that a wide variety of threat actors, from cybercriminal gangs to nation-state actors, are now taking advantage of this vulnerability.

To mitigate the risk, QUIRSO has published a YARA rule for identifying reverse_ssh builds, which organizations can use to review their vCenter instances for signs of compromise. Szadkowski warns that attacks are ongoing and recommends a forensic investigation of potentially affected systems to rule out an existing compromise. While patching is essential, it’s clear that vigilance and quick action are necessary to stay ahead of this threat campaign.

Ultimately, the exploitation of CVE-2026–59310 serves as a stark reminder of the importance of timely patching and thorough vulnerability management. Organizations must be prepared to act quickly in response to newly disclosed vulnerabilities, and invest in robust detection and response capabilities to mitigate the risk of attack.


Source: Dark Reading — 2026-08-13